revFADP · SR 235.1

The revised Swiss data protection act, read practically

The revised FADP has applied since 1 September 2023, with no transition period. For most SMEs the workload is smaller than feared — but in one respect it is less comfortable than the GDPR: the fine falls on the responsible person, not the company.

Short answers

Since when?
1 September 2023, with no transition period. The 1992 act was replaced outright.
Who does it protect?
Natural persons only. Data about legal entities — protected under the old act — no longer falls within scope.
Do we need a record of processing activities?
Companies with fewer than 250 employees are generally exempt, provided the processing carries low risk and sensitive personal data is not processed at scale.
How large are the fines?
Up to CHF 250,000 — and they are directed at the responsible natural person, not the company. That is the central difference from the GDPR.
Can we send customer documents by email?
The act prohibits no channel. It requires measures appropriate to the risk. For documents containing personal data a mailbox is weak control: no revocation, no traceability, copies sitting in other people’s inboxes.

What changed from the old act

The revision moved Swiss data protection closer to European standards without copying the GDPR. Four changes are noticeable in daily practice:

The penalty targets the person, not the company

This is the point missing from most summaries. The GDPR fines undertakings, scaled to group turnover. The revised FADP takes a different route: fines of up to CHF 250,000, directed at the responsible natural person.

For an SME that means the company does not pay — the individual responsible for the breach does, in practice often a member of management. The amounts are lower than under the GDPR; the personal exposure is far more direct.

Intent is required; negligent breaches are not caught in the same way. That eases the position for businesses making a genuine effort, and sharpens it for those knowingly leaving a known gap open.

What an average SME actually has to do

The effort is routinely overestimated, because GDPR material gets transposed onto Swiss circumstances. For a business without large-scale data processing it comes down to five things:

Disclosure abroad — and what it does not cover

Personal data may be disclosed abroad where the destination country ensures adequate protection; the Federal Council maintains a list. Absent adequacy, appropriate safeguards are needed — in practice usually standard contractual clauses.

A common misreading: these rules concern your own processors — where your data is hosted and processed. They are not triggered because your customer happens to use a foreign mail provider. The recipient’s choice is theirs, not a disclosure decision of yours.

The converse also holds: where you choose the storage location, you also choose how much work this proof becomes. That is the real argument for hosting in Switzerland — not the retention obligation, which despite widespread claims prescribes no location at all.

What this means for documents in a mailbox

The act prohibits no transmission channel. It requires measures appropriate to the risk. So the question is not whether email is permitted, but whether a mailbox is adequate control for the data in question.

For quotes, contracts and invoices containing personal data, the answer runs against the mailbox. An attachment, once sent, cannot be recalled. Copies sit in inboxes you do not control. Who opened or forwarded the document cannot be established. And access belongs to the person holding the mailbox rather than to the company — when they leave, the traceability leaves with them.

This is not a compliance catastrophe. It is a weakness of known size, and knowing it is already part of the organisational measure the act asks for.

Duties at a glance

Duty Applies to a typical SME Note
Privacy notice / duty to inform Yes On any collection of personal data
Technical and organisational measures Yes Appropriate to the risk, not maximal
Processor contracts Yes Hosting, software, external service providers
Handling access requests Yes Prepare the process, do not improvise
Reporting security breaches Only where risk is high To the FDPIC, as soon as possible
Record of processing activities Usually no Exempt below 250 employees where risk is low
Data protection impact assessment Usually no Only for high-risk processing

What athemi covers — and what it does not

athemi does not make you compliant. Compliance is a matter of process and documentation, not software. What athemi addresses is the technical part that most often fails in practice: customer documents travelling as attachments through mailboxes, where they end up belonging to nobody.

Try athemi free

Frequently asked

Does the GDPR or the FADP apply to us?

Possibly both. The FADP applies to processing connected to Switzerland. The GDPR applies in addition where you offer goods or services to people in the EU or monitor their behaviour. A Swiss SME with EU customers regularly sits under both regimes — the requirements largely overlap.

Do we need a data protection officer?

For private companies in Switzerland this is voluntary. The FADP recognises the role and attaches certain reliefs to it, but does not mandate it — unlike the GDPR in particular constellations.

What counts as sensitive personal data?

Among other things data on health, religious or political views, social assistance measures, administrative or criminal proceedings, and now genetic and biometric data uniquely identifying a person. In ordinary B2B work it rarely arises — in personnel files it regularly does.

Must we report every data incident?

No. Reportable breaches are those likely to result in a high risk to the personality or fundamental rights of the people affected. An appointment confirmation sent to the wrong address will not normally reach that threshold; open access to personnel files certainly does.

Related guides

Sources

This page summarises the legal position in general terms and is not legal advice. Whether and to what extent a duty applies to you depends on your specific processing.

Last reviewed: 2026-07-25